Bharat Club IT Policy

Our commitment to responsible, secure, and lawful use of technology — protecting every member’s data and keeping our digital community safe.

📋
Overview

The Bharat Club is committed to protecting the privacy, security, and integrity of all member information across every digital touchpoint — from our website and mobile app to social media and internal systems. This policy applies to all registered members (ordinary, associate, honorary, and life members), committee members, staff, volunteers, vendors, and anyone who accesses Bharat Club’s digital platforms.

What this covers

Member registration system (online & offline) Official Bharat Club website Mobile app (iOS & Android) Social media & digital engagement Computers, laptops, tablets & mobile devices Email systems & messaging platforms Member portals & databases Cloud services & software

Our goals

1
Protect member data
Safeguard the personal data and privacy of all Bharat Club members in accordance with PDPA 2010
2
Secure our systems
Ensure the integrity, availability, and confidentiality of all Bharat Club IT systems
3
Define acceptable use
Set clear rules for using our website, mobile app, and social media platforms
4
Respond to incidents
Establish clear procedures for detecting, reporting, and responding to cybersecurity incidents
5
Stay compliant
Ensure compliance with Malaysian laws and international IT standards at all times
6
Promote good digital citizenship
Encourage responsible, ethical, and lawful digital behaviour among all members and administrators

Child Safety & Minor Protection

The Bharat Club is committed to providing a safe and appropriate digital environment for all users, with dedicated protections in place for children and minors across our mobile app, website, and all digital platforms. This commitment is aligned with the Apple App Store Children’s Category guidelines, the Google Play Families Policy, the Malaysian Personal Data Protection Act 2010 (PDPA), and the Communications and Multimedia Act 1998 (CMA). The following provisions form a binding part of our IT Policy and apply to all members, administrators, vendors, and any party who interacts with Bharat Club’s digital platforms.

Any minor under the age of 18 who wishes to register for the Bharat Club app or access member-exclusive digital services must do so with the prior written consent of a parent or legal guardian. This consent must be provided at the point of registration and retained on record by the club. Parents and guardians retain the right to access, review, correct, or request the deletion of their child’s personal data at any time by submitting a written request to our designated Data Protection Officer (DPO). The Bharat Club also supports the use of native parental control features available on iOS through Apple’s Screen Time and on Android through Google’s Family Link, and encourages parents to enable these controls for minor users.

Legal framework

LegislationWhat it means for us
Personal Data Protection Act 2010 (PDPA)How we collect, process, and store your personal data
Computer Crimes Act 1997 (CCA)Protection against unauthorised access and misuse of systems
Communications and Multimedia Act 1998 (CMA)Standards for online content and digital communications
Electronic Commerce Act 2006 (ECA)Legal validity of digital transactions and e-signatures
Digital Signature Act 1997 (DSA)Governs electronic signatures used in member registration
Copyright Act 1987 (Amended 2012)Protects our digital content, website materials, and intellectual property
Cybersecurity Act 2024National cybersecurity obligations and incident reporting requirements
Societies Act 1966Governs our registration and operations as a registered society
Malaysia National Cybersecurity Policy (NCSP 2020–2024)National cybersecurity strategy and standards we align with
🏛️
IT Governance & Responsibilities

Management committee

Sets the direction for all IT decisions, approves this policy and major IT changes, and ensures the club allocates adequate budget and oversight to maintain safe, reliable technology systems.

IT coordinator / appointed officer

Manages day-to-day IT operations, ensures system security and backups are in place, coordinates with external IT vendors, and reports all incidents to the Management Committee promptly.

Members & users — what we expect

Expected of you
Use club IT resources responsibly
Keep your login credentials private and secure
Report any security incidents or suspicious activity promptly
Not permitted
Access unauthorised systems or other members’ data
Distribute malicious software of any kind
Use club resources for illegal, offensive, or unrelated political activities
Share passwords or impersonate other members

Policy review cycle

This policy is reviewed annually by the IT Committee, or sooner if there are significant changes to Malaysian law, technology, or Bharat Club operations. All amendments require Committee approval, and all members are notified of material changes. Previous versions are archived for reference.

🔐
How We Handle Your Data

We collect only the information needed to manage your membership and communicate with you — nothing more. All data handling complies fully with the Personal Data Protection Act 2010 (PDPA) and the Electronic Commerce Act 2006.

Information we may collect

Full name (as per MyKad or Passport) NRIC or passport number Date of birth & gender Email address & mobile number Residential address Emergency contact details Payment & fee transaction records Profile photo (optional — with your explicit consent only)
A Privacy Notice is presented to all members at the point of registration — physical or digital — informing you of the data collected, the purpose, your rights under PDPA 2010, and the contact details of our Data Protection Representative.

Our seven PDPA commitments

PrincipleOur commitmentHow we implement it
GeneralCollect only for lawful, stated purposesRegistration form with clearly stated purpose
Notice & ChoiceTell you what we collect and why, before we collect itPrivacy notice displayed at registration
DisclosureNever share your data with third parties without your consentWritten consent required for any third-party sharing
SecurityApply reasonable security measures to protect your dataEncrypted database and strict access controls
RetentionKeep data only as long as necessary3-year retention policy with annual purge review
Data IntegrityEnsure your data is accurate, complete, and currentMember self-service update portal
AccessLet you view and correct your own data at any timeMember login portal for viewing and updating data

How long we keep your data

Active members
Throughout membership
Former members
Up to 3 years after expiry
Financial records
7 years (Income Tax Act 1967)

How we secure your data

All member data is stored on secured servers accessible only to authorised personnel. Passwords are hashed using industry-standard algorithms (bcrypt or SHA-256 minimum). Physical membership forms are kept in locked cabinets. Digital records are backed up weekly to a secure, off-site or cloud location. All data transfers use encrypted channels (TLS 1.2 or above).

Your consent & how to withdraw it

Your consent is always explicit — we never use pre-ticked boxes. Marketing communications require a separate opt-in from operational consent. You may withdraw your consent at any time via our online portal or by written notice. Withdrawing consent does not affect the legality of any processing that took place before withdrawal.

🛡️
Cybersecurity

Access control

Every user accesses only the systems relevant to their role (Role-Based Access Control). Administrative access always requires multi-factor authentication (MFA). Shared or default passwords are never permitted. Access rights are reviewed every quarter and removed immediately when someone leaves a role or their membership ends. All access activity is logged and monitored.

Password requirements

Minimum length
10 characters
Must include
Upper, lower, numbers & symbols
Admin rotation
Every 90 days
Reuse restriction
Cannot reuse last 5 passwords

Password managers are recommended for all committee members who handle IT systems.

What happens when a security incident occurs

1
Detect
Identify and verify the incident; document the time and nature of the breach
2
Contain
Isolate affected systems; disable compromised accounts; prevent further spread
3
Notify
Alert the President, IT Committee, and affected members within 72 hours — a PDPA obligation
4
Report
Report to CyberSecurity Malaysia (MY-CERT) at mycert.org.my if the breach is significant
5
Eradicate
Remove malicious code, patch vulnerabilities, and restore from a clean backup
6
Recover
Restore all services, conduct a post-incident review, and update the incident register
7
Learn
Debrief the team, update policies and controls, and notify staff and members as needed

Data backup & recovery

Backup frequency
Daily (automated)
Storage locations
2+ geographically separate
Backup integrity test
Monthly restoration drills
Recovery target (RTO)
Critical systems within 24 hrs
Max data loss (RPO)
24 hours

Devices & personal devices (BYOD)

All club-owned devices must be password-protected with screen locks enabled. Lost or stolen devices must be reported to the IT Coordinator immediately. Personal devices used for club activities are permitted provided club data is properly protected, devices are secured with a password or biometric lock, and club data is deleted when no longer needed. The club reserves the right to restrict access if a security risk is identified.

Email, messaging & collaboration tools

All official communications should use club-approved email or messaging platforms. Messages must remain respectful and professional at all times. Bulk emails and announcements require prior authorisation.

Encryption

Encryption is applied to protect sensitive information from unauthorised access or disclosure. As a community-based, non-profit organisation, we adopt reasonable and proportional encryption controls. While advanced enterprise-grade encryption may not always be practical, minimum accepted standards are always applied wherever personal or financial data is involved.

Software patches

Standard patches
Applied within 30 days of release
Critical / zero-day
Applied within 72 hours
🌐
Our Website

Ownership & governance

The Bharat Club maintains sole ownership of its official website, registered under a .my or .com.my domain where applicable. Domain management and renewals are handled by the IT Committee with an annual review. The website displays our registered society name consistent with the Societies Act 1966. A dedicated Website Administrator is appointed to oversee all content and technical operations.

Content standards

All content published on the website must be factually accurate, non-defamatory, and respectful of all races, religions, and groups. Content must be reviewed and approved by an authorised committee member before it goes live. Financial matters, event registrations, and official club matters must be verified by the relevant officer. Copyrighted materials (images, videos, text) must only be used with proper licensing or attribution.

Under Sections 211 and 233 of the Communications and Multimedia Act 1998, publishing offensive, obscene, false, or menacing content online carries penalties of up to RM50,000 in fines or imprisonment.

Website security measures

HTTPS with valid SSL/TLS certificate (min TLS 1.2) Web Application Firewall (WAF) Protection against SQL injection, XSS & CSRF attacks Two-factor authentication (2FA) on all admin login pages Annual penetration testing (or after significant changes) Website access logs retained for a minimum of 12 months CMS, plugins & frameworks kept up to date with security patches

Cookies & tracking

A Cookie Consent Banner is shown to all visitors in compliance with PDPA 2010. Essential cookies operate without consent; analytics and marketing cookies require your explicit opt-in. A Cookie Policy page is published detailing all cookie types, their purposes, and opt-out mechanisms. Third-party tools such as Google Analytics are disclosed in our Privacy Policy.

Accessibility

Our website aims to comply with Web Content Accessibility Guidelines (WCAG) 2.1 Level AA. Content is made available in both Bahasa Malaysia and English wherever possible. Mobile responsiveness is mandatory across all website pages.

Mandatory pages on our website

Privacy Policy (PDPA 2010) Terms & Conditions of Use Cookie Policy Member Registration Terms Disclaimer & Limitation of Liability
📱
Mobile App

The Bharat Club’s official mobile app is available exclusively through the Google Play Store (Android) and Apple App Store (iOS). No other sources are authorised. All app releases undergo internal QA and security testing before deployment.

Development standards

The app is developed following secure coding practices based on the OWASP Mobile Top 10 framework. The app’s version, developer information, and privacy policy are accurately reflected in the app store listing at all times.

Your privacy in the app

The app requests only the permissions it strictly needs — nothing more (Principle of Least Privilege). Location, camera, contacts, and other sensitive permissions are requested only with your explicit consent. All data processed through the app fully complies with PDPA 2010. Our in-app Privacy Policy is accessible at any time, both before and after account creation. All data transmitted via the app is encrypted using TLS 1.2 or higher.

Content policy

The app’s target age range is clearly specified. Adult-only content is strictly restricted. Any advertisements displayed within the app are child-friendly and appropriate for all users.

App security features

Password minimum
8 characters (letters, numbers, symbols)
Biometric login
Optional (fingerprint / face ID)
Session timeout
30 minutes of inactivity
Security patches
Released within 30 days

The app implements certificate pinning to prevent man-in-the-middle (MITM) attacks, and includes root/jailbreak detection to warn users of compromised device security.

Push notifications

We only send push notifications to members who have explicitly opted in. Notifications are always relevant, non-spammy, and limited to Bharat Club-related matters. You can manage your notification preferences at any time within the app settings. Notification data is never used for profiling or sold to third parties.

In-app payments (where applicable)

All in-app payment features comply with the Payment Card Industry Data Security Standard (PCI-DSS) and are processed exclusively via Payment Service Providers licensed under Bank Negara Malaysia guidelines. We never store your full card number, CVV, or sensitive payment credentials on your device or our servers. All payment receipts are accessible to you and retained for seven (7) years.

📣
Social Media & Digital Engagement

Our official channels

Bharat Club maintains official verified accounts on approved platforms including Facebook, Instagram, X (Twitter), YouTube, TikTok, and WhatsApp Official. All account credentials are managed by the IT Committee. At least two authorised administrators have access to each account. Personal accounts of committee members are never used to officially represent the club.

What we post — and what we don’t

We share
Club event announcements and updates
Member achievements and recognition
Educational and informational content
Community activities and volunteering
Approved promotional partnerships
We never post
Racial, religious, or political content (CMA 1998 S.211)
Defamatory statements against any person or entity
Fake news or unverified information
Member personal data without consent
Obscene, violent, or offensive material

Member conduct on social media

When discussing or representing Bharat Club on your personal accounts, please clearly distinguish your personal views from official club positions, avoid sharing confidential club information or internal deliberations, refrain from making statements that could embarrass or defame the club, and do not impersonate the club or its officials on any platform. Report any harmful content related to the club to the IT Committee immediately.

Under Section 233 of the CMA 1998, transmitting obscene, false, threatening, or offensive content online with intent to annoy can result in fines up to RM50,000 or up to one year’s imprisonment, or both. All members and administrators must exercise due caution in all digital communications.

Sponsored & influencer content

Any sponsored or paid partnership posts must be clearly disclosed as #Advertisement or #Sponsored, and approved by the Bharat Club Committee before publication. The club does not engage in misleading commercial practices in violation of the Consumer Protection Act 1999.

Community moderation

Official social media pages are moderated by designated personnel. Comments that are abusive, violate community standards, or contain prohibited content are removed promptly. A Social Media Community Guideline is published and pinned on all official pages. Repeated violations may result in a member being banned from Bharat Club digital platforms.

WhatsApp & Telegram groups

Official club groups are managed by designated Group Admins from the committee. Members must not share fake news, political content, or personal data of others in these groups. Forwarding confidential club matters outside official groups is strictly prohibited. Group admins reserve the right to remove members who repeatedly violate group guidelines.

Acceptable Use

These guidelines apply to all IT resources provided by the Bharat Club — including Wi-Fi at club premises, computers, the website, mobile app, and all social media platforms.

You’re welcome to

Access club information, announcements, and event details Communicate with club members and administrators on club matters Register for events, pay membership fees, and update your profile Participate in club-sanctioned online discussions and social activities

Strictly prohibited

Unauthorised access to other members’ accounts or data (CCA 1997, Section 3) Hacking, phishing, or attempting to compromise club systems Distributing malware, viruses, or malicious code Sharing pirated software, media, or copyrighted content (Copyright Act 1987) Using club platforms for commercial activities without approval Impersonating other members or club officials Cyberbullying, harassment, or intimidation of any kind Spreading fake news or misinformation (Penal Code, Section 505)

Consequences of violations

SeverityExampleOutcome
MinorSharing unverified informationWarning and mandatory awareness training
ModerateHarassment, repeated AUP breachTemporary suspension of digital access
SevereHacking, data theft, fraudMembership termination and police report
🤝
Third-Party Vendors & Service Providers

When we engage external IT service providers, software vendors, cloud services, or contractors, we hold them to the same standards we hold ourselves. All engagements comply with applicable Malaysian laws and the club’s data protection obligations.

Vendor assessment

All vendors who process personal data on our behalf must sign a Data Processing Agreement (DPA) compliant with PDPA 2010. They must demonstrate adequate technical and organisational security measures. Cloud providers are assessed for data sovereignty — member data is preferably stored on servers in Malaysia or in countries with equivalent data protection laws.

What every vendor contract must include

Clear data handling, retention, and deletion obligations Notification to us within 24 hours of any security breach affecting our data Permission for us to conduct security audits upon reasonable notice Prior written approval required before sub-contracting any of our data processing
📞
Your Rights & How to Get Help

Your rights under PDPA 2010

Access the personal data we hold about you Request correction of inaccurate or incomplete data Withdraw your consent for data processing (subject to legal obligations) Ask us about how your data is being processed

Submit any data access, correction, or complaint request in writing to our designated Data Protection Officer (DPO). We will respond within 21 days of receiving your request. Complaints about IT policy breaches or data misuse can be directed to the IT Chairperson. Unresolved complaints may be escalated to the Personal Data Protection Commissioner at pdp.gov.my.

Regulatory contacts

Personal Data Protection Commissioner
pdp.gov.my — PDPA 2010 breaches and complaints
CyberSecurity Malaysia (MY-CERT)
mycert.org.my — 1-300-88-2999 — Cybersecurity incidents
MCMC
mcmc.gov.my — Online content and communications violations
Royal Malaysia Police (PDRM)
Commercial Crime Division — Computer Crimes Act violations and cybercrime